Malware Broker Behind US Hacks Now Teaching Computer Skills in China

Yu Pingan is one of the few alleged Chinese hackers to have been arrested and convicted in the US crackdown.

Advertisement
By Reuters | Updated: 24 December 2019 18:56 IST
Highlights
  • A Chinese malware broker is back at his old workplace
  • Yu Pingan had pleaded guilty to conspiracy to commit computer hacking
  • He spent 18 months in a San Diego federal detention centre

A high school instructor, he had been arrested at Los Angeles International Airport in August 2017

A Chinese malware broker who was sentenced in the United States this year for dealing in malicious software linked to major hacks is back at his old workplace: teaching high-school computer courses, including one on Internet security. Yu Pingan, who spent 18 months in a San Diego federal detention centre, had pleaded guilty to conspiracy to commit computer hacking. A high school instructor, he had been arrested at Los Angeles International Airport in August 2017 upon arriving with a group of teachers to observe a US university. A Reuters reporter found him teaching at his old school here last month.

Yu was sentenced by a federal judge in February to time served and allowed to return to China. The victims of the hacking conspiracy included microchip supplier Qualcomm, aerospace and defence firm Pacific Scientific Energetic Materials, and gaming company Riot Games, according to the judgment. Exactly what was stolen in the computer breaches wasn't disclosed in public court filings.

Qualcomm declined to comment. A Riot Games spokesman said the company lost no data. Pacific Scientific didn't respond to requests for comment.

Advertisement

Yu specialises in computer network security and programming, according to court records. The malware he provided in the conspiracy included a rare software tool called Sakula that granted hackers remote control over computers. It's unclear who authored the malware or how Yu obtained it.

Advertisement

Sakula has been linked to some of the most notorious cyber-attacks of the decade. In addition to the intrusions detailed in the case against Yu, these include hacks of US health insurer Anthem, where millions of patient records were exposed, and the US Office of Personnel Management, in which the personal information of millions of current and former US government employees and contractors was compromised. Yu wasn't accused of involvement in those two breaches.

His prosecution was one of a series of criminal cases against Chinese nationals Washington has brought in recent years, in response to what the Americans say is a concerted campaign by China's military and security ministry to steal technology from Western companies.

Advertisement

In another case involving Sakula malware, the US last year alleged that two Chinese intelligence officers and a team of recruited hackers repeatedly intruded into Western companies' computer systems for more than five years.

Many of the Chinese defendants in the series of hacking cases haven't been apprehended. Yu is one of the few alleged Chinese hackers to have been arrested and convicted in the US crackdown.

Advertisement

In addition to jail time, Yu was ordered to pay nearly $1.1 million in restitution to five companies that were victims of the hacking. The fine was to be paid in instalments of $100 a month, with no interest, according to the judgment. The payment schedule would take more than 900 years to complete.

Jeremy Warren, a San Diego criminal defence attorney who represented Yu, said: "With a Chinese national, a school teacher, there's no real expectation of payment."

Yu's 18 months in federal prison, he said, was no "walk in the park."

China's Ministry of Foreign Affairs said it had "no understanding" of the Yu case. "We resolutely oppose any type of cyber-attack, and we investigate and crackdown on any cyber attack occurring inside China or making use of Chinese Internet infrastructure," the ministry spokesperson's office said.

The ministry added that it had no knowledge of other cases alleging Chinese hacking of US companies, and it accused Washington of displaying a "cold war mentality" in its tech-related prosecutions.

Yu, according to court filings by US prosecutors, went by the nickname "Goldsun." He was accused of conspiring with other Chinese individuals to use malware to hack into the computer networks of companies in the US and elsewhere.

An affidavit from Federal Bureau of Investigation Special Agent Adam James alleged that Yu provided Sakula and other malware used in the case. Citing seized communications between Yu and two unindicted co-conspirators, James alleged that Yu had installed "an unauthorised backdoor" on an unidentified company's computer network to gain remote access.

The conspirators' cyber intrusions included so-called "watering hole attacks," in which malicious software infects the computers of visitors to compromised websites. "This is akin to a predator waiting to ambush prey at the location the prey goes to drink water," a court document stated.

Last month, Reuters found Yu, who is 39, teaching at Shanghai Commercial School, a state-run vocational technical high school in central Shanghai. US officials told Reuters that Yu had been teaching there prior to his arrest.

Digital signs outside classrooms indicated Yu was teaching at least two basic computer courses, including one called "Basic English for Internet Security." One of his former students, a computer science major who is now in China's military, said he couldn't answer questions about Yu because of "political reasons" and that the school had instructed him not to discuss the matter.

On November 1, a Reuters reporter saw Yu at an office on the school's campus. Dressed in a red and blue plaid Oxford shirt, he declined to answer questions. Yu called a school official, who arrived with a security guard and escorted the reporter off the campus. The school official called Yu's situation a private matter.

"It's his own experience, and it has nothing to do with the school," she said.

© Thomson Reuters 2019

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: US, China, Yu Pingan
Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 15T With 50-Megapixel Selfie Camera Debuts in India: See Price
  2. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  3. India's Indigenous Vikram Microprocessor Showcased at Semicon India 2025
  4. Realme 15T 5G India Launch Today: All You Need to Know
  5. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  1. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  2. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  3. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  4. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  5. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  6. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  7. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  8. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  9. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  10. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.